RM Logo
Technical Rating: 
Support Home PageSupport
Print This PagePrint This Page
Add to 'My Library' Add to 'My Library'

RM Unify - AD Sync Config Tool fails to display one or more users in the Users container
Published Date : 23 Mar 2018   Last Updated : 23 Jul 2024   Content Ref: TEC6154274  





Symptoms

Some or all of your users fail to display in the main Users container in the RM Unify AD Sync Config Tool. In addition to this, the AD Sync log files contains the following error:

"ERROR,"ProcessADUser","Failed to process changes for AD User <ADUser> (<GUID>) - System.Runtime.InteropServices.COMException (0x8007200A): The specified directory service attribute or value does not exist."
where <ADUser> is a missing user and <GUID> is a unique GUID.



Cause

The identitysyncservice user needs read permission on containers in Active Directory in order to search for users, e.g. CN=Users. If this permission is missing then the error will display.

By default, the identitysyncservice user is granted group membership of account operators and domain users during installation of RM Unify AD Sync. This group membership is sufficient to grant the user read permission on AD containers, unless customised permissions have been set on one or more containers.



Procedure

To confirm insufficient permissions are causing the issue
  1. On the AD Sync server, open the AD Sync Config Tool.
  2. Click Services, Stop.
  3. On a domain controller, signed in as an administrator, open 'Active Directory Users and Computers' and browse to the Users OU.
  4. Right-click the identitysyncservice user account and click Properties, 'Member Of tab', and then Add.
  5. Type administrators and click OK, OK.
  6. On the AD Sync server, open the AD Sync Config Tool.
  7. Click Services, Start.
  8. Wait 20 minutes and check if the AD Sync log file contains the same error. If the error no longer appears in the log file and missing users have started to appear in the AD Sync Config Tool then there is an issue with permissions.
  9. Repeat steps 1 to 7, remove the identitysyncservice user from the administrator's group and continue with troubleshooting.

To check permissions on an AD container
  1. Log on to a domain controller as an administrator and open 'Active Directory Users and Computers'.
  2. Click View, Advanced Features and navigate down to the Users container.
  3. Right-click and select Properties.
  4. Click Security, Advanced.
  5. Click the Effective Access tab and then click 'Select a user'.
  6. Type identitysyncservice and click OK.
  7. Click 'View effective access'.
  8. Confirm the user has been granted (i.e. there is a green tick) next to the following permissions:
    • 'List contents'
    • 'Read all properties'
    • 'Read permissions'
  9. Repeat steps 2 to 7 for all other containers.

What to do if you have corrected permissions

If you followed the above and found you needed to correct some permissions then complete the following:

  1. On the AD Sync server, open the AD Sync Config Tool.
  2. Click Service, Stop.
  3. Click Server, Start.
  4. Wait 20 minutes and check if the missing users are now visible in the Users container in the AD Sync Config Tool.


More Information

If you still get the same error after completing a change of permissions then please raise a support call with the RM Unify Cloud Support team so we can help you further.


FEEDBACK
Did the information in this article help answer your question?
 Yes
 No
Please add any comments about this article in the box below. If you answered No then it is important you tell us why so that we can change the article if required. We can only respond if you log in to the RM Support website or provide your contact details. Note: If you need help with a technical query, please log a call online or telephone our support team.
Thank you for your feedback, which is sent directly to the RM Knowledge team. We address every message received with the intention of improving our Knowledge Library articles. If you have an unresolved technical issue, please contact RM Support.


If this article has not helped provide a solution then it is also possible to log a call...



Document Keywords: actions, gafe, gapps, Google Apps, Google Apps for Education, TEC6154274, unify, rm unify


Please read - important disclaimer information.
http://www.rm.com/_RMVirtual/Includes/csredirect.asp?cref=&title=Standard Content Disclaimer


Top Of PageTop of page